Good morning. Tuesday brings a critical hole in a WordPress plugin sitting on hundreds of thousands of small business websites, the largest wave of Apple spyware warnings anyone has tracked, and a reminder that the AI tool you standardized on last year may not be around next month. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT.
A WordPress forms plugin running on more than 600,000 sites can hand an attacker complete control. Researchers disclosed a critical flaw in Forminator Forms, tracked as CVE-2026-15748 and rated 9.8 out of 10, that lets an unauthenticated attacker upload executable files and take over a vulnerable site outright. Exploitation requires a form that combines a file upload field with a select field, which describes a lot of ordinary job applications, quote requests, and support intake forms. The fix shipped on July 31 in version 1.56.2, so the real question is whether anyone has logged into your site’s admin panel since then. It is easy to treat the company website as marketing rather than infrastructure, but a compromised site becomes a malware host wearing your domain name, and your customers are the ones who pay for that. Read more at The Hacker News
Apple sent its biggest wave of spyware warnings yet, and the people who investigate these attacks say the volume is like nothing they have seen. On Friday Apple notified customers in 110 countries that their devices had been targeted with commercial spyware of the kind governments buy, and the nonprofit help line Apple points victims toward reported 30 to 40 percent more people reaching out than after previous rounds. Researchers at Citizen Lab called the scale and geographic spread of the public reports unprecedented, and part of the jump is likely because Apple now surfaces these alerts on the lock screen, in Settings, and by email instead of one place that is easy to miss. Most small business owners are not spyware targets, but the executives, attorneys, and finance people in your orbit occasionally are, and an alert like this is exactly the sort of thing an employee shrugs off as a scam. Make sure your team knows a notification like that is real and worth escalating, and that Lockdown Mode is already sitting on every iPhone and Mac you own. Read more at TechCrunch
An AI automation tool that businesses built real workflows on is going dark next month. Relay, a well funded startup that positioned itself as a modern replacement for Zapier, confirmed it will cut off paying customers on September 14, with free accounts already shut off as of August 15, while its founder and part of the team head to Google to work on Chrome. This is the unglamorous side of the AI boom: a lot of these tools are venture-funded experiments, and the outcome that is a win for the founders is a migration project for you, on their timeline. If something quietly important in your business runs through a young AI vendor, the useful exercise is to write down today what you would do if it announced a 30-day shutdown. Keeping your automation logic documented outside the vendor’s interface costs an afternoon and saves a scramble. Read more at TechCrunch
Most companies are already letting AI agents make changes in production, and the guardrails are the hard part. A new Caylent survey found that 59.5 percent of enterprise leaders are running AI agents autonomously in production rather than confining them to pilots, with 67.5 percent using or evaluating agents for automated testing, 60.5 percent for incident response, and 43 percent for writing and committing code. Notably, 83 percent said guardrails matter as much as or more than the intelligence of the model itself, which is a telling shift from where this conversation was a year ago. If you are considering giving an AI tool the ability to change something rather than just suggest it, the questions worth answering first are what it can touch, what still requires a human approval, and who reviews the log afterward. Deciding that up front is far cheaper than discovering the answer during an incident. Read more at ChannelE2E
GitLab shipped an emergency patch for a flaw that lets a stranger delete your code. GitLab pushed an out-of-band critical release on Monday for CVE-2026-19478, rated 9.4 out of 10, which under certain conditions lets an unauthenticated attacker remotely modify or delete public projects and user data through a GraphQL directive. Only self-managed installations need to act, with fixes in versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11, and the older 18.2 through 18.10 branches do not get a fix at all despite sitting inside the affected range. Most conversations about source code risk center on theft, but destruction is the version that stops work the same afternoon, and plenty of small companies self-host precisely because they wanted tighter control over their intellectual property. If your business writes software, or pays someone who does, the two questions worth asking today are whether that server has been updated and whether anyone has actually tested restoring it from backup. Read more at The Hacker News
Follow Up
Follow-up to Friday’s VMware item: that vCenter flaw is now being used to deploy ransomware. When we covered CVE-2026-59310 last week, attackers were exploiting exposed vCenter servers to plant backdoors. Researchers have now attributed the campaign to a suspected China-linked group and documented it deploying ransomware built from leaked Babuk code, which turns a quiet persistence problem into an encrypted-environment problem. Broadcom patched the flaw on July 29 and there is still no workaround besides applying it. If your business runs VMware, or your IT provider does on your behalf, this is worth a direct question today rather than an assumption, because ransomware landing at the virtualization layer takes every server sitting on top of it at once. Read more at The Hacker News
Sponsored by Lucky 13 Solutions
Business in Motion. Tech in Sync. Lucky 13 Solutions is a managed services provider helping small and midsize businesses keep their IT reliable, secure, and well-supported, without needing a full in-house team. Learn more at l13s.com.
Get the Business IT News Roundup in your inbox:
How this gets made: stories come from my own reading and from AI-assisted research and drafting, all reviewed and edited by me before anything goes out. The commentary is mine, sources are linked so you can read the original, and any errors are mine to own. If something looks wrong, reply and tell me.